What Is Data Protection?, A Quick Introduction

6 min readLast updated By Marc Grob

Introduction

Data protection does not primarily protect data, it protects people. The legal regime aims to ensure that natural persons retain control over information about themselves: who knows it, what it is used for, with whom it is shared and how long it is kept. In Switzerland and the EU two legal regimes apply, often in parallel for Swiss companies: the revised Federal Act on Data Protection (DSG) and the EU General Data Protection Regulation (GDPR).

This introduction provides a compact orientation. It explains:

  • What personal data is and which categories are especially sensitive
  • The six principles every processing activity is measured against
  • Who is the controller and who is the processor
  • The key rights of the data subject
  • The Swiss supervisory structure (FDPIC / EDÖB) and its sanctions
  • When the DSG applies, when the GDPR applies and when both apply

The article is aimed at people who need to understand the topic professionally without going deep into the articles, board members, executive management, marketing, HR, engineering. For deeper topics we link at the end.

What is personal data

Under Art. 5(a) DSG and Art. 4(1) GDPR, personal data is ‘any information relating to an identified or identifiable natural person’. Three points are important:

  • Natural person: legal persons are not in scope of the GDPR; under the DSG they have not been protected since 1 September 2023 (the old DSG still covered them).
  • Identifiability: it is sufficient that the person can be identified with reasonable effort, including via pseudonyms, IP addresses, cookie IDs, device fingerprints. Only true anonymisation (re-identification impossible even with all available means) takes data outside the scope.
  • Format does not matter: structured databases, Excel sheets, audio recordings, photos and videos, location logs, biometric templates, all captured.

Within personal data sits a subgroup of data requiring special protection (Art. 5(c) DSG) or special categories (Art. 9 GDPR): religious, philosophical, political or trade-union views, health, intimate sphere, racial origin, biometric and genetic data, plus data on social assistance and criminal prosecutions. Stricter processing conditions apply.

The six principles

The DSG (Art. 6) and the GDPR (Art. 5) regulate almost identical principles. Every processing must meet them cumulatively:

  1. Lawfulness: a valid legal basis must exist, consent, contract, legal obligation, vital interest, public interest or legitimate interest.
  2. Good faith / fairness: no hidden processing, no deception.
  3. Purpose limitation: data is collected for specified, explicit and legitimate purposes and not further processed in incompatible ways.
  4. Data minimisation / proportionality: only the necessary minimum, an address field nobody uses does not belong on the form.
  5. Accuracy: data must be kept up to date; incorrect data must be rectified or deleted.
  6. Storage limitation, integrity and confidentiality: data may only be retained as long as the purpose requires; it must be protected by appropriate technical and organisational measures.

The GDPR adds the accountability principle (Art. 5(2)): the controller must not only achieve compliance but be able to demonstrate it at any time. The DSG does not name accountability explicitly, but the FDPIC expects the same evidence in supervision.

Controller, processor, third party

Whoever bears responsibility for a processing activity is the controller (Art. 5(j) DSG; Art. 4(7) GDPR). The controller is the one who determines purposes and means, that is, who decides why and how data is processed. Where two or more parties jointly determine these, joint controllership applies (Art. 26 GDPR).

Anyone processing data on behalf of the controller without deciding purposes and means is the processor (Art. 5(k) DSG; Art. 4(8) GDPR). Examples: cloud providers, IT service providers, payroll bureau, mailing house. The relationship must be governed by a written data processing agreement (DPA) under Art. 9 DSG or Art. 28 GDPR.

Finally there are third parties: everyone else who is not controller, processor or data subject. Disclosing to a third party is a transfer and itself requires a legal basis.

In practice: in every supplier relationship, the first step is to determine whether it is processing on behalf or independent processing, the consequences for contract and liability are significant. Frequently mis-classified are advertising vendors, AI providers and platform marketplaces.

The rights of the data subject

At the heart of every modern data protection regulation are the data subject rights. Under the DSG (Art. 25–32) and the GDPR (Art. 15–22) they are very similar:

  • Access (Art. 25 DSG; Art. 15 GDPR): which data is processed about me, for what purposes, to whom is it disclosed, how long is it retained, where does it come from?
  • Rectification: incorrect data must be corrected.
  • Erasure: data can be deleted unless a legal retention requirement applies.
  • Restriction of processing: data is ‘frozen’, for example during a dispute about accuracy.
  • Data portability (Art. 28 DSG; Art. 20 GDPR): data I have provided is returned in a machine-readable format.
  • Objection (GDPR Art. 21): particularly for legitimate interest processing and direct marketing.
  • Right to human review of automated individual decisions (Art. 21 DSG; Art. 22 GDPR).
  • Withdrawal of consent at any time without disadvantage.

Response deadline under the DSG: 30 days from receipt (Art. 25(7)). Response deadline under the GDPR: one month, extendable by two months (Art. 12(3)). Both regimes allow free first access.

Supervision in Switzerland, the FDPIC

The Federal Data Protection and Information Commissioner (FDPIC / EDÖB) is the national supervisory authority under Art. 43 et seq. DSG. Since 1 September 2023 its powers have been significantly expanded:

  • Opening of investigations on its own initiative or upon report
  • Ordering measures (e.g. modification, interruption or termination of processing)
  • Publishing decisions
  • Advising controllers
  • Commenting on federal draft legislation
  • International cooperation, especially with EU supervisors and the EDPB

The FDPIC cannot impose criminal fines itself, Art. 60 et seq. DSG are part of private criminal law and are prosecuted by cantonal authorities. Fines up to CHF 250,000 against the natural person responsible are possible; aggravated offences include breach of the access duty (Art. 60(1)(a)), the duty to cooperate and the deliberate provision of false information.

Under the GDPR the sanctions machine is much bigger: fines up to EUR 20 million or 4% of global group turnover (Art. 83(5)). Swiss companies with GDPR exposure therefore face a double sanctions risk.

DSG, GDPR or both, when does which apply

The applicability of the two regimes is a discipline in itself. Simplified rules of thumb:

FADP applies to any processing of personal data by private parties domiciled in Switzerland and to facts with effects in Switzerland (Art. 3(1) DSG). It captures practically every Swiss business activity involving personal data.

GDPR applies under Art. 3 in three constellations: (1) establishment in the EU, typically headquarters of the group or a subsidiary; (2) targeting principle: offering goods or services to persons in the EU, irrespective of payment; (3) monitoring behaviour of persons in the EU (e.g. web tracking).

For a Swiss SME this means in practice: anyone running a website read in Germany, France or Italy (language version, prices in EUR, delivery into the EU, EU phone number) is very likely caught by the GDPR. Anyone staying in Switzerland and only delivering in Swiss francs is often not. Where this is unclear, the overall picture counts, isolated indicators (a few orders from Germany) are usually not enough.

Those caught by both build their programme GDPR-compliant and automatically meet the DSG too. Those captured by the DSG alone can run leaner, but should deliberately leave a GDPR bridge open for future market expansion.

How SIDD supports you

SIDD accompanies Swiss companies across the full maturity ladder, from the first baseline call to ongoing DPO mandates. Our Swiss data protection advisory delivers the methodological foundation and a record of processing under Art. 12 DSG. Where there is EU exposure, we add the GDPR DPO function and, if Art. 27 GDPR applies, the role of EU representative.

For training your teams and management, our privacy workshops are available, we teach the foundations sketched in this article in practical form, with case examples from Swiss supervisory practice. For a first maturity baseline use our contact form; a fixed-price proposal for a GAP analysis or mandate follows within five working days via the offer.

Need help putting this into practice? SIDD operates the matching service.
See service →

What Is Data Protection?, A Quick Introduction

INSIGHT

Data Protection
24 May 2026
Marc Grob
What is data protection? An introduction to personal data, principles, roles, data subject rights, FDPIC supervision and when FADP or GDPR applies.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.